CVE-2015-4202
Summary
| CVE | CVE-2015-4202 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-06-20 14:59:00 UTC |
| Updated | 2016-12-28 18:02:00 UTC |
| Description | Cisco IOS 12.2SCH on uBR10000 router Cable Modem Termination Systems (CMTS) does not properly restrict access to the IP Detail Record (IPDR) service, which allows remote attackers to obtain potentially sensitive MAC address and network-utilization information via crafted IPDR packets, aka Bug ID CSCua39203. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Cisco | Ios | 12.2(33)sch | All | All | All |
| Operating System | Cisco | Ios | 12.2sch | All | All | All |
| Operating System | Cisco | Ios | 12.2\(33\)sch | All | All | All |
| Operating System | Cisco | Ios | 12.2sch | All | All | All |
| Operating System | Cisco | Ios | 12.2\(33\)sch | All | All | All |
| Hardware | Cisco | Ubr10000 Cable Modem Termination System | All | All | All | All |
| Hardware | Cisco | Ubr10000 Cable Modem Termination System | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco uBR10000 Series Universal Broadband Routers Discloses Potentially Sensitive Information to Remote Users - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Cisco uBR10000 Series Universal Broadband Routers CVE-2015-4202 Information Disclosure Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Cisco uBR10000 Series Universal Broadband Routers Information Disclosure Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.